Linux Kernel Wi-Fi Driver Vulnerability Involving PMKID Data Leakage
CVE-2026-98350
What is CVE-2026-98350?
A vulnerability exists in the Linux kernel's brcmfmac Wi-Fi driver, which pertains to the management of the PMKID data. During initialization, if the auth_status is not zeroed out, sensitive data can unintentionally leak from the stack into the firmware. This occurs particularly when the SSID is shorter than 32 bytes or when specific parameters (params->pmkid) are set. If the PMKID is not properly passed to the firmware, it may retain stale data, causing issues during subsequent authentication attempts. This flaw could potentially allow for unauthorized access or denial of service in Wi-Fi network connections.
Affected Version(s)
Linux 66f909308a7c05082919ff214a0bbe2a76aa0283
Linux 66f909308a7c05082919ff214a0bbe2a76aa0283 < 6fba6233e9ca7718661e53555a3961c58772c21a
Linux 66f909308a7c05082919ff214a0bbe2a76aa0283